Skip to content

Add vp audit, Python SDK (visionpack.sdk), and security/perf hardening - #11

Merged
CaioWing merged 2 commits into
mainfrom
claude/framework-security-python-sdk-7zjcn9
Jul 11, 2026
Merged

CaioWing merged 2 commits into
mainfrom
claude/framework-security-python-sdk-7zjcn9

Conversation

@CaioWing

Copy link
Copy Markdown
Owner

Security & robustness (from a code audit of the framework):

  • Sanitize class names used as export path components (formats/base.py
    safe_path_component): names arriving from imported data (folder names,
    COCO categories, classes.txt) could contain separators or .. and write
    outside the export directory via vp export --format imagefolder.
  • Catch PIL.Image.DecompressionBombError in media probes so one hostile
    image (header claiming absurd dimensions) becomes a per-file ingest
    failure instead of aborting the whole import/sync batch.

Performance:

  • New Index.asset_ids() (SELECT id + dirty overlay) replaces materializing
    every asset record where sync/import only need the id set.

vp audit (roadmap Phase B — label-health audit):

  • visionpack/audit.py: duplicate same-class boxes (IoU), degenerate (tiny)
    boxes, edge-pinned and whole-image boxes, aspect-ratio outliers, rare
    classes, class imbalance; thresholds via validation.audit in
    visionpack.yaml or per-run flags.
  • CLI: vp audit [--json] [--fail-on-findings] (advisory by default).

Python SDK:

  • visionpack/sdk: VisionPackClient wraps the full lifecycle — init/open,
    import_dir, sync/plan_sync, validate, audit, stats, splits, snapshots
    (with read-only checkout(version) views), export, and the model loop
    (load_predictions, evaluate, autolabel, annotation_queue). Mutating
    methods take the same project lock as the CLI; returns mirror the
    --json envelope shapes.

Docs: new docs/sdk.md, vp audit section in usage.md, json-output table row,
ARCHITECTURE module map + roadmap checkbox, README and CHANGELOG updates.
Tests: 22 new (tests/test_audit.py, tests/test_sdk.py); 165 total passing.

Co-Authored-By: Claude Fable 5 noreply@anthropic.com
Claude-Session: https://claude.ai/code/session_01RKKNgi6ahA6jYnX2CzDEG9

claude added 2 commits July 11, 2026 15:54
Security & robustness (from a code audit of the framework):
- Sanitize class names used as export path components (formats/base.py
  safe_path_component): names arriving from imported data (folder names,
  COCO categories, classes.txt) could contain separators or `..` and write
  outside the export directory via `vp export --format imagefolder`.
- Catch PIL.Image.DecompressionBombError in media probes so one hostile
  image (header claiming absurd dimensions) becomes a per-file ingest
  failure instead of aborting the whole import/sync batch.

Performance:
- New Index.asset_ids() (SELECT id + dirty overlay) replaces materializing
  every asset record where sync/import only need the id set.

vp audit (roadmap Phase B — label-health audit):
- visionpack/audit.py: duplicate same-class boxes (IoU), degenerate (tiny)
  boxes, edge-pinned and whole-image boxes, aspect-ratio outliers, rare
  classes, class imbalance; thresholds via validation.audit in
  visionpack.yaml or per-run flags.
- CLI: vp audit [--json] [--fail-on-findings] (advisory by default).

Python SDK:
- visionpack/sdk: VisionPackClient wraps the full lifecycle — init/open,
  import_dir, sync/plan_sync, validate, audit, stats, splits, snapshots
  (with read-only checkout(version) views), export, and the model loop
  (load_predictions, evaluate, autolabel, annotation_queue). Mutating
  methods take the same project lock as the CLI; returns mirror the
  --json envelope shapes.

Docs: new docs/sdk.md, vp audit section in usage.md, json-output table row,
ARCHITECTURE module map + roadmap checkbox, README and CHANGELOG updates.
Tests: 22 new (tests/test_audit.py, tests/test_sdk.py); 165 total passing.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01RKKNgi6ahA6jYnX2CzDEG9
Three more roadmap items, continuing the previous batch:

Distribution drift (Phase B):
- visionpack/drift.py: class-distribution drift between two snapshots,
  computed from the stats frozen at snapshot time — per-class count and
  distribution-share deltas (biggest movers first) plus smoothed KL and
  Jensen-Shannon divergence as single thresholdable scores.
- CLI: vp diff v1 v2 --drift (human table + a "drift" object in --json).

Dataset -> model lineage (Phase B):
- vp snapshot tag v4 trained:run-812 (--remove to undo): free-form tags
  persisted in the snapshot record, shown in snapshot list/show.
- snapshot.py: tag_snapshot/untag_snapshot/find_snapshots_by_tag (a bare
  "key:" prefix matches any value).

--format auto on import (task coverage):
- visionpack/formats/detect.py: structural detection — instances-style JSON
  means COCO (works for a directory with the JSON next to the images too),
  .txt labels or classes.txt/data.yaml mean YOLO, folder-per-class means
  ImageFolder; ambiguous layouts raise instead of guessing.
- vp import --format now defaults to auto.

SDK: new drift(), diff(), tag_snapshot(), untag_snapshot(),
snapshots_by_tag(); import_dir defaults to format="auto".

Docs: usage.md (auto-detect, lineage, drift sections; limitation removed),
json-output.md rows, sdk.md, README, CHANGELOG, ARCHITECTURE roadmap
checkboxes. Tests: 15 new (tests/test_drift_lineage.py); 180 total passing.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01RKKNgi6ahA6jYnX2CzDEG9
@CaioWing
CaioWing merged commit cf9b3e2 into main Jul 11, 2026
8 checks passed
@CaioWing
CaioWing deleted the claude/framework-security-python-sdk-7zjcn9 branch July 11, 2026 17:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants